Estimated reading time: 8 minutes
Three-quarters of organizations that suffered a material cyberattack and business interruption in the past year blew through their recovery time objective. On average, recovery took nearly twice as long as the objective they had set.
That figure does not appear in Cohesity’s press release. It sits on page six of the full report, and it is the number cyber insurance underwriters should read first.
Business interruption cover is built on time. Waiting periods, indemnity periods and sub-limits all assume a recovery timeline that roughly holds. The Association of British Insurers noted last month that business interruption and recovery costs are frequently the largest single portion of a cyber claim. If the underlying recovery objective is wrong by a factor of two, every number built on top of it moves.
Cohesity’s fifth annual Global Cyber Resilience Report, published on 16 September, surveyed 3,200 IT and security decision-makers through Vanson Bourne.
What Cyber Recovery Planning Assumes
The report frames every recovery plan as a bet, and it names the five assumptions the bet rests on.
Eighty-six percent assume business operations can safely resume once core systems are restored. Eighty-five percent assume decision-makers will have adequate information when recovery actions are needed. Eighty-four percent assume sufficient visibility into dependencies to sequence recovery in advance. Eighty-three percent assume incidents can be fully contained before recovery begins. Seventy-nine percent assume recovery proceeds in a mostly linear sequence without significant backtracking.
Ninety-three percent rely on all five to some degree.
Cohesity’s own observation on that is the sharp one. Reliance on those assumptions runs highest among organizations expressing complete confidence in their resilience strategy, and lowest among those who think their strategy needs work. The report’s reading is that confidence may be rooted more in faith than in proven testing.
Eighty-eight percent expect their plan to require workarounds or improvisation during an actual attack.
Restoring Systems Is Not The Same As Recovering
The central argument is that recovery plans aim at the wrong finish line. Seventy-eight percent focus more on restoring systems than on maintaining critical operations and serving customers during recovery.
The consequences show up after the systems come back.
Among organisations hit by a material attack, 63% were delayed by having to recover data and reconcile business activity that happened after the most recent backup. Sixty percent were delayed by lack of confidence that restored data and systems were clean. Sixty percent hit identity or access problems that stopped users reaching systems. Fifty-nine percent found dependencies that had not been validated or were not working.
Sixty-nine percent encountered all seven delay factors the study measured.
The scope moved too. Seventy percent saw the range of affected systems expand beyond their initial assessment during recovery.
Two findings sit underneath that. Sixty-eight percent do not always test identity systems after an attack to confirm that persistence mechanisms and attacker access are gone. And independent third-party forensic review was the least common verification step before reconnecting restored systems, used by 39%.
Seventy-six percent said they prioritise speed of recovery over certainty that restored systems are clean and safe.
Get The Weekly Cyber Insurance News Upload
Subscribe to our newsletter!
The Minimum Viable Company Gap
The concept Cohesity puts at the centre of the report is the Minimum Viable Company: the smallest version of a business that can keep serving customers while broader recovery continues.
Thirty-seven percent have formally documented one. Only 22% have documented and tested it.
Among that 22%, the payoff is measurable. Ninety-two percent say it informed or influenced recovery priorities, and 64% say it directly determined what was restored first during a material attack.
That distinction between documented and tested is the one a carrier can actually ask about. It mirrors the argument Chao Cheng-Shorland made on the Cyber Insurance News podcast this month, where she described the gap between recovery after failure and continuity during it as the most vulnerable period in any incident.
Where The Money Goes
The spending data explains a lot of the rest.
Respond and Recover together take 34% of cyber resilience investment across the five NIST framework functions. Protect leads, followed by Identify and Detect. Seventy-three percent of organisations agree their own investment is weighted too heavily toward prevention at the expense of response and recovery.
Cohesity reports no meaningful change in that allocation from last year.
Eighty-four percent also agree that differences between IT and security teams can delay decisions about when systems are safe to bring back online. That is an organisational cost with a direct downtime consequence, and it is not a control any application form asks about.
AI Is Operational Before It Is Recoverable
Ninety-nine percent of respondents use AI systems, applications, workflows or machine learning models. Thirty-nine percent say their recovery plans comprehensively account for attacks targeting them.
Fifty-eight percent are not very confident they could verify the integrity of AI models and associated data after an incident. Fifty-six percent say they are not well prepared to detect, contain and recover from unintended or incorrect actions taken by AI agents, copilots or AI workflows.
That second figure matters more than it looks. It is not about attackers. It is about an organisation’s own AI doing something it should not, which is the category Anthropic documented this month when its models took unauthorised actions against third-party systems during evaluations.
There is a maturity effect worth noting. Among organisations whose plans comprehensively address AI attack scenarios, 71% are very confident verifying AI integrity. That falls to 24% for partial coverage and 16% for minimal. The preparedness figures follow the same pattern, at 80%, 22% and 11%.
On frontier AI, 83% say their plans would need moderate to significant change to handle capabilities like automated vulnerability discovery, exploit development and multi-step intrusions. Three percent say their current plans are equipped for it.
Two Surveys, One Week, Opposite Directions
Cohesity reports that 73% of organisations experienced a material cyberattack in the past 12 months, up from 54% a year earlier.
Proofpoint’s Voice of the CISO, published a week earlier, found CISOs expecting a material attack in the next 12 months fell from 76% to 61%.
Different questions, expectation against experience, and different respondent pools. But the two headline numbers move in opposite directions in the same month, and anyone quoting both should say which they are measuring.
Cohesity’s confidence data leans toward the Proofpoint reading being optimistic. Complete confidence in resilience strategy fell from 47% in 2025 to 37% in 2026, while those saying their strategy needs improvement rose from 53% to 62%.
Take The Cyber Insurance News Survey
Respondents get results first.
How To Read This Report
Three limits are worth stating.
Cohesity sells backup, recovery and data security. A report concluding that recovery plans are inadequate points directly at its own category, and the recommendations section points at its own tools. That does not make the survey data wrong. It does mean the framing is not neutral.
The sample covers organizations with 1,000 or more employees across 12 countries, fielded in July. There is no small business data here, which matters given how much of the cyber book sits below that threshold.
And material cyberattack is defined by the respondent, as an incident with measurable financial, operational, reputational or customer impact. That self-definition likely explains why 73% sits high against claims-derived datasets.
The recovery time finding survives all three. An organization reporting that its own recovery took twice as long as its own objective is not being sold anything. It is reporting against a number it set itself.
FAQ – Cyber Recovery Planning
How long does cyber recovery actually take?
Longer than planned. Cohesity found 76 percent of organizations that suffered a material cyberattack exceeded their recovery time objective, with recovery averaging nearly twice as long as the objective they had set themselves.
Why does restoring systems not mean recovery is complete?
Because restored systems still need verification. Sixty percent reported delays from lacking confidence that restored data was clean, 60 percent hit identity and access problems, and 63 percent had to reconcile business activity that occurred after the last backup.
What is a Minimum Viable Company?
The smallest version of a business that can keep serving customers while broader recovery continues. Only 22 percent of organizations have formally documented and tested one. Among those, 64 percent say it directly determined what was restored first.
Are recovery plans ready for AI incidents?
Mostly not. Ninety-nine percent of organizations use AI systems, while 39 percent say their recovery plans comprehensively account for attacks targeting them. Fifty-six percent are not well prepared for unintended actions by AI agents or copilots.
Where are organizations spending on cyber resilience?
Overwhelmingly on prevention. Respond and Recover together account for 34 percent of cyber resilience investment across the NIST framework functions, and 73 percent of organizations agree their own spending is weighted too heavily toward prevention.
Related Cyber Insurance Posts
- The Ransom Bot Is Not Haggling – It Is Taking Away Your Thinking Time
- Cohesity Report Highlights Overconfidence in Cyber Resilience Amid Rising Threats(Opens in a new browser tab)
- Cyber Insurance Policy Limits Exposed: Only Resilience Restores Investor Trust(Opens in a new browser tab)
- Bridging Cyber Risk Exposure with an 831(b) Plan: Why the New Federal Court Ruling Changes the Game(Opens in a new browser tab)
- Most CISOs Admit They Are Not Ready For The Next Big Cyberattack(Opens in a new browser tab)
2 thoughts on “Recovery Took Twice As Long As Planned. Nobody Priced For That.”